Security & Architecture
How Arihant AI secures your financial ledgers, inventory transactions, and mission-critical cloud ERP workloads with defense-in-depth engineering.
Cloud Infrastructure & Hosting Topology
Arihant AI runs on resilient, enterprise-grade cloud infrastructure engineered to eliminate single points of failure and protect Indian business continuity.
Tier-4 Data Centers
Hosted in India's top-tier, bank-grade secure data centers with 24/7 biometric security, redundant power feeds, and a 99.99% continuous uptime guarantee.
Indian Data Sovereignty
All primary database clusters and automated snapshot volumes reside within Indian geographical borders (AWS Mumbai/Hyderabad and Oracle Cloud Mumbai regions).
99.9% High Availability
Architected with active health check probes, automated container recovery, database failover clusters, and elastic scaling to absorb month-end GST filing peaks.
Cryptographic Data Encryption
We employ rigorous cryptographic standards to protect confidential corporate data at every transition and rest state:
| State | Cipher Standard | Implementation Scope |
|---|---|---|
| Data In Transit | TLS 1.3 / TLS 1.2 with HSTS | Enforced across all web portals, mobile application endpoints, REST APIs, and background webhooks with Perfect Forward Secrecy. |
| Data At Rest | AES-256 Bit Encryption | Applied to all PostgreSQL relational databases, document filestores, attachments, and disk block volumes using hardware security modules. |
| Backup Archives | GPG Encrypted AES-256 | Daily snapshot packages are cryptographically signed and stored in immutable, write-once object storage buckets. |
| Credential Storage | PBKDF2 with SHA-512 & Salt | User passwords and authentication tokens are never stored in plaintext and cannot be reverse-computed by company administrators. |
Granular Access Control & Identity Governance
Internal security relies on the principle of least privilege (PoLP) and segregation of operational duties:
- Role-Based Access Control (RBAC): Pre-configured and customizable access roles (e.g., Accounts Manager, Billing Clerk, Warehouse Incharge, Purchase Officer) prevent unauthorized viewing of financial journals or sensitive customer data.
- Multi-Factor Authentication (MFA): Native TOTP authenticator app support (Google Authenticator, Microsoft Authenticator) protects administrative accounts against credential compromise.
- Immutable Audit Logging: Every critical transaction, invoice alteration, stock adjustment, and user login is recorded in permanent audit logs detailing the actor, IP address, timestamp, and exact before-and-after values.
- Session Timeouts & CSRF Defense: Automated token expirations and strict SameSite CSRF cookies protect against cross-site session hijacking.
Automated Backups & Disaster Recovery
Business continuity guarantees your operational data survives localized infrastructure outages:
Automatic continuous backups protect every single transaction with zero data loss (RPO under 15 mins), allowing full system restoration to the exact second if ever needed with full failover drills.
- Automated Daily Snapshots: Full system snapshots are executed every 24 hours during off-peak hours and archived in geo-redundant storage.
- Automated Restore Drills: Backup integrity is verified weekly through automated synthetic restoration tests to confirm zero archive corruption.
- On-Demand Client Exports: Enterprise administrators can export complete database backups in standardized formats (.sql, .zip) at any time directly from the system management console.
Application Security & Continuous Testing
Security is embedded directly into our software development lifecycle (DevSecOps):
- OWASP Top 10 Mitigation: Our QWeb XML and Python microservices are hardened against SQL injection, cross-site scripting (XSS), server-side request forgery (SSRF), and broken object-level authorization (BOLA).
- Automated Static & Dynamic Code Analysis: Every production code change undergoes automated vulnerability scanning (SAST/DAST) in our CI/CD pipelines before deployment.
- Periodic Penetration Testing: Independent external cybersecurity auditing teams conduct comprehensive gray-box penetration assessments against production endpoints annually.
Statutory & Industry Standards Alignment
Arihant AI is built to meet and exceed regulatory standards applicable to Indian manufacturing, logistics, and professional accounting firms:
- Digital Personal Data Protection Act, 2023 (DPDP Act): Comprehensive technical and organizational measures ensuring lawful, transparent personal data stewardship.
- Information Technology Act, 2000 & SPDI Rules: Strict adherence to reasonable security practices and procedures for sensitive personal data or information.
- ISO/IEC 27001 & SOC-2 Type II: Infrastructure providers and data center facilities maintain active, audited ISO 27001:2022 and SOC-2 Type II security attestations.
- Indian GST Statutory Invoicing Integrity: Cryptographically generated e-Invoices with IRN and signed QR codes ensuring statutory non-tampering under GST rules.
24/7 Security Operations & Incident SLA
Our operational telemetry proactively detects anomalies before they affect production:
- Automated DDoS Mitigation: Cloudflare and AWS Shield infrastructure absorb volumetric layer-3/4 and layer-7 distributed denial-of-service attacks.
- Intrusion Detection & SIEM: Centralized real-time log analysis monitors abnormal authentication volume, privilege escalation attempts, and unexpected outbound transfers.
- Incident Response SLA: In the unlikely event of a confirmed security incident, our incident response team initiates containment within 60 minutes and delivers formal statutory notification to affected customers within 72 hours.
Responsible Disclosure & Security Contact
We welcome responsible vulnerability disclosures from certified security researchers and enterprise security teams: